Mobyproject / Moby
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-42306 | Moby: Race condition in docker cp allows bind mount redirection to host path | HIGH | 7.2 | Jun 12, 2026 |
| CVE-2026-41568 | Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap | MEDIUM | 6.1 | Jun 12, 2026 |
| CVE-2025-54410 | Moby's Firewalld reload removes bridge network isolation | MEDIUM | 5.2 | Jul 30, 2025 |
| CVE-2025-54388 | Moby's Firewalld reload makes published container ports accessible from remote hosts | MEDIUM | 5.1 | Jul 30, 2025 |
| CVE-2024-36623 | moby: Race Condition in Moby's streamformatter Package | HIGH | 8.7 | Nov 29, 2024 |
| CVE-2024-36621 | moby: Race Condition in Moby's Snapshot Layer Handling | HIGH | 8.7 | Nov 29, 2024 |
| CVE-2024-36620 | github.com/moby/moby: NULL Pointer Dereference in Moby | MEDIUM | 5.7 | Nov 29, 2024 |
| CVE-2024-32473 | Moby IPv6 enabled on IPv4-only network interfaces | MEDIUM | 6.5 | Apr 18, 2024 |
| CVE-2024-29018 | External DNS requests from 'internal' networks could lead to data exfiltration | HIGH | 7.5 | Mar 20, 2024 |
| CVE-2024-24557 | Moby classic builder cache poisoning | HIGH | 7.8 | Feb 1, 2024 |
| CVE-2023-28840 | moby/moby's dockerd daemon encrypted overlay network may be unauthenticated | HIGH | 8.7 | Apr 4, 2023 |
| CVE-2023-28841 | moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted | MEDIUM | 6.8 | Apr 4, 2023 |
| CVE-2023-28842 | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated | MEDIUM | 6.8 | Apr 4, 2023 |
| CVE-2022-36109 | Moby vulnerability relating to supplementary group permissions | MEDIUM | 6.3 | Sep 9, 2022 |
| CVE-2022-27652 | cri-o: Default inheritable capabilities for linux container should be empty | MEDIUM | 5.3 | Apr 18, 2022 |
| CVE-2022-24769 | Default inheritable capabilities for linux container should be empty | MEDIUM | 5.9 | Mar 24, 2022 |
| CVE-2021-41089 | `docker cp` allows unexpected chmod of host files | MEDIUM | 6.3 | Oct 4, 2021 |
| CVE-2021-41091 | Insufficiently restricted permissions on data directory in Docker Engine | MEDIUM | 6.3 | Oct 4, 2021 |
| CVE-2018-12608 | moby: cert signing bypass | HIGH | 7.5 | Sep 10, 2018 |
| CVE-2018-10892 | docker: container breakout without selinux in enforcing mode | MEDIUM | 5.3 | Jul 6, 2018 |
| CVE-2017-16539 | docker: The DefaultLinuxSpec function does not block /proc/scsi pathnames | MEDIUM | 5.9 | Nov 4, 2017 |
Showing 1 to 21 of 21 CVEs